Anthropic today unveiled Project Glasswing, a defensive cybersecurity initiative in partnership with 12 tech giants including Apple, Microsoft, Google, AWS, and NVIDIA. The project leverages the unreleased Claude Mythos Preview model, which autonomously discovered thousands of high-severity zero-day vulnerabilities across every major operating system and browser within weeks.
27-Year-Old OpenBSD Bug and a FFmpeg Flaw Missed by 5 Million Scans
Three case studies highlighted Mythos Preview's capability. It found a 27-year-old vulnerability in OpenBSD, widely considered one of the most secure operating systems, allowing remote crashes via simple connection. In FFmpeg, it uncovered a 16-year-old flaw that had survived 5 million automated test runs undetected. The model also chained multiple Linux kernel vulnerabilities to achieve privilege escalation from user to full system control.
Benchmark Dominance Over Opus 4.6
Mythos Preview significantly outperformed Anthropic's current strongest public model Claude Opus 4.6 across benchmarks: CyberGym 83.1% vs 66.6%, SWE-bench Verified 93.9% vs 80.8%, Terminal-Bench 2.0 82.0% vs 65.4%, GPQA Diamond 94.6% vs 91.3%. In Firefox JavaScript shell exploit testing, it generated 181 working exploits compared to Opus 4.6's 2.
$100M Commitment and 12-Founding Partner Alliance
The founding partner list includes AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, with over 40 additional organizations granted extended access. Anthropic committed up to $100 million in Mythos Preview usage credits and donated $4 million to open-source security initiatives. CrowdStrike CTO Elia Zaitsev warned: "The window from vulnerability discovery to exploitation has collapsed. What once took months now takes minutes with AI."
Not Released to Public: A Double-Edged Sword
Anthropic stated it will not release Mythos Preview to the public for now, citing the same capability that finds vulnerabilities could become a weapon in malicious hands. Palo Alto Networks CPO Lee Klarich noted the model "not only changes the game for finding hidden vulnerabilities but signals attackers will soon find more zero-days and develop exploits faster than ever." Anthropic plans to add new safety measures in future Claude Opus models and has engaged with U.S. government officials on the model's offensive and defensive capabilities.
The first Glasswing report is expected in 90 days. Beyond the number of patches, the key question is whether this AI-driven vulnerability discovery model can scale and become institutionalized.

